SiteScan.top

Scan report for minsk.by

5 pages crawled — 6947 words, 37 images and 913 links read straight off the pages and checked for accessibility, performance, SEO, security, forms, links and infrastructure. {distinct} distinct problems found, counted 127 times across the pages.

Report updated 2026-09-06

Category scores

Overall
81/100
SEO
81/100 · Issues: 14
Accessibility
89/100 · Issues: 16
Performance
87/100 · Issues: 22
Security
10/100 · Issues: 49
Privacy
98/100 · Issues: 4
HTML validity
82/100 · Issues: 10
Forms
98/100 · Issues: 1
Links
90/100 · Issues: 2
Console
Not measured
Infrastructure
90/100 · Issues: 9

Quick Wins

High-impact, low-effort fixes, ranked by what this scan actually found.

  • Send a Strict-Transport-Security header — Browsers refuse to fall back to plain HTTP for this domain.
  • Send a Referrer-Policy header — Internal URLs stop leaking to third-party sites.
  • Set the Secure flag on every cookie — Cookies stop travelling in the clear where the site is reachable in the clear.
  • Set HttpOnly on the session cookies — A script injected into the page can no longer read the session cookie.
  • Make every id on the page unique — Anchors, labels and scripts reach the element they were pointing at.
  • Send a Permissions-Policy header — Camera, microphone and geolocation stay switched off for embedded content.

What the site checks found

  • Medium — The WordPress REST route /wp-json/wp/v2/users answers to anyone, listing the login name of every author on the site.
  • Low — xmlrpc.php is enabled — it is the endpoint password-guessing tools use because it lets them try many passwords in one request.
  • Low — No /.well-known/security.txt — anyone who finds a vulnerability has to guess where to report it.
  • Medium — Sitemap URLs answering with an error: 2 of 5 checked — the sitemap is sending crawlers at pages that are gone.
  • Medium — Internal links leading to an error page: 2 of 10 checked.
  • Low — The domain publishes no MX records, so it cannot receive email.
  • Medium — No SPF record — anyone can send email that claims to come from this domain.
  • Medium — No DMARC record at _dmarc — nothing tells receiving servers what to do with mail that fails the SPF check.
  • Low — No CAA record — any certificate authority may issue a certificate for this domain.
  • Low — The host has no AAAA record — visitors on IPv6-only networks reach it only through their carrier gateway.
  • Low — The zone is not signed with DNSSEC, so a forged DNS answer cannot be detected.

Other sites scanned recently

Scan your own site

Get the same diagnostic report for your website in under a minute.